(Tenant) Restrict creation of new Azure DevOps organizations.
Why This Matters
Without restrictions, any user in your tenant can create new Azure DevOps organizations, which may operate outside your security policies and visibility. This can lead to shadow IT where unmanaged Azure DevOps instances store sensitive code, credentials, or intellectual property without proper governance. Controlling organization creation reduces the risk of data sprawl and ensures all development activities remain under your security umbrella.
What Aether365 Checks
This check verifies that your tenant has a policy in place to restrict the creation of new Azure DevOps organizations to authorized administrators only. It appears in the Aether365 dashboard under the microsoft-365 checks category (ID AZDO.1034) and flags any tenant where self-service creation is still enabled for all users.